|
 |
|
DARFUNS Message Boards! (TechVTS)
Got a computer virus/security question? Ask it here and get instant helpfull answers.
Or Brows other computer security questions and answers by community
Login - Register
Remove Winpc Defender rogue spyware
WinPC Defender is a new rogue anti-spyware program discovered by security analyst S!Ri and is a clone of the programs named XP Police Antivirus and IE Security. Win-pc-defender.com is a fraudulent website involved in the corrupt scheme of promoting the infamous rogue anti-spyware called WinPC Defender. Win-pc-defender.com has been designed in conformance with the general features inherent to hijacker-sites. You may wonder what it means? Well, first of all, you are very unlikely to follow Win-pc-defender.com domain by your own wish - you will be typically forcedly redirected to this URL. And the redirection itself is possible if your browser settings allow this. And the browser must have been attacked by the hijacker which is technically a backdoor Trojan. Sounds like an intricate technique, but it proved to work for the enormous quantity of hijackers existing on the web. Win-pc-defender.com is just one of such browser hijackers. Win-pc-defender.com will display tons of misleading adware praising the sponsoring rogue WinPC Defender.
In addition, Win-pc-defender.com will probably welcome you with its fake scanner that runs and reports a variety of infections in your system that cannot be removed unless you buy WinPC Defender license. Do not get tricked by any of the deceptive content you may get on Win-pc-defender.com – it’s all fabricated and pursues the one and only goal to scare you into wasting your money for the useless registered version of WinPC Defender scam. Besides being worthless, WinPC Defender is quite dangerous if you install its full version – it may slow your PC down and make it exposed to outer hazards. Remove WinPC Defender and its hijacker Win-pc-defender.com ASAP if infected.
When WinPC Defender is installed it will scan your computer and display a variety of infections that cannot be removed unless you purchase the program. These infections, though, do not actually exist on your computer. Instead WinPC Defender is programmed to always show the same scan results regardless of the computer it is run on. It does this in order to scam you into thinking that you are infected and hoping that you will purchase the program in order to remove the infections. When S!Ri was testing this rogue he had registered his copy of the program to see if even the registered version would remove these so-called infections. Even when the program was registered, it still would not remove any of the infections and continued to state that your computer was infected.
A byproduct of this program running on your computer is an endless barrage of false warnings and Internet Explorer hijackings. These alerts are programmed to stay on top of your desktop so that if you have any running applications you need to close the alerts before you can get back to the screen you were working on. Even more annoying is that when you close these alerts you will then have to wade through a bunch of "Are you sure?" screens before the alert will close. The alerts that we saw when testing included a Firewall Warning and a Trojan alert. The text of these alerts are:
Trojan detected!
A piece of malicious code was found in your system which can replicate itself if no action is taken. Click here to have your system cleaned by WinPC Defender
Firewall Warning
Hidden file transfer to remote host was detected.
This program, in addition to the nag screens, will hijack your Internet Explorer browser so that it randomly shows a warning when you are browsing the web. While browsing the web, you may be shown a Insecure Internet Activity. Threat of virus attack screen, instead of the page you are trying to browse to. This screen will contain an option to continue to the page or purchase WinPC Defender. Regardless of the choice you select, you will still be brought to the purchase page for this program.
As you can see, this program has only one purpose and that is to trick you into thinking you are infected so that you purchase it. Please ignore any warnings that this program may display and instead use the free removal guide below to remove WinPC Defender and any associated malware.
How to remove Win-pc-defender.com hijacker manually:
Manual removal of Win-pc-defender.com hijacker and attendant malware is feasible if you have sufficient expertise in dealing with program files, system processes, .dll files and registry entries.
The associated files to be deleted are listed below:
%UserProfile%\Desktop\Launch WinPC Defender.lnk
%UserProfile%\Local Settings\Temp\delwdef2008.bat
%UserProfile%\Local Settings\Temp\[Random Name].tmp
%Program Files%\WinPC Defender\data.dat
%Program Files%\WinPC Defender\FwHookDrv.sys
%Program Files%\WinPC Defender\HOSTS.hst
%Program Files%\WinPC Defender\Manual.url
%Program Files%\WinPC Defender\options.xml
%Program Files%\WinPC Defender\reserve.dat
%Program Files%\WinPC Defender\rules
%Program Files%\WinPC Defender\Rules.txt
%Program Files%\WinPC Defender\siren.wav
%Program Files%\WinPC Defender\Support.url
%Program Files%\WinPC Defender\svo.scf
%Program Files%\WinPC Defender\temp
%Program Files%\WinPC Defender\Uninstall.exe
%Program Files%\WinPC Defender\Uninstall_st_st_.exe
%Program Files%\WinPC Defender\vfile
%Program Files%\WinPC Defender\WDefDemo.exe
%Program Files%\WinPC Defender\Web.url
%WINDOWS%\ieocx.dll
The related registry entries to be removed are as follows:
HKEY_CURRENT_USER\Software\WinPC Defender
HKEY_CLASSES_ROOT\CLSID\{96ad72e4-2e2b-4ffc-a5bb-279c2714af12}
HKEY_CLASSES_ROOT\IEocxApp.IEocx
HKEY_CLASSES_ROOT\IEocxApp.IEocx.1
HKEY_CLASSES_ROOT\Interface\{4B66E1DF-4DE3-4CDA-83B5-11673EADAB0B}
HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
HKEY_CLASSES_ROOT\TypeLib\{A54DC52D-7AAD-4D40-A126-337211631EDC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96ad72e4-2e2b-4ffc-a5bb-279c2714af12}
HKEY_CURRENT_USER\Control Panel\don’t load “scui.cpl”
HKEY_CURRENT_USER\Control Panel\don’t load “wscui.cpl”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “sysav”
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run “Content”
Please, be aware that manual removal of Win-pc-defender.com hijacker is a cumbersome procedure and does not ensure complete deletion of the malware, due to the fact that some files might be hidden or may automatically reanimate themselves afterwards. Moreover, manual interference of this kind may cause damage to the system. That’s why we strongly recommend automatic removal of Win-pc-defender.com hijacker, which will save your time and enable avoiding any system malfunctions and guarantee the needed result.
Download Win-pc-defender.com Automatic Remover
OR, If manuall removal guide is confusing for you, use SUPER ANTI SPYWARE to remove this threat
 download Super Anti Spyware (FREE)
|
| | |
 |
|
|